AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-18754

CRITICAL · CVSS 9.1 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The vulnerability lies in the embedded static RSA private key within the firmware of the Lighttpd web server, which is used for TLS termination. This exposure compromises the confidentiality and integrity of HTTPS communications, allowing attackers to decrypt traffic and potentially spoof the server. Organizations using this web server should prioritize remediation to protect sensitive data and maintain secure communications.

CVE
CVE-2026-18754
Severity
CRITICAL
CVSS
9.1
EPSS
0.31%

Original NVD Description

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.